# JSON input for kibana dashboards

**URL:** <https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946>\
**Category:** Kibana\
**Created:** [January 17, 2018, 9:27pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946 "2018-01-17T21:27:16Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 17, 2018, 9:27pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/1 "2018-01-17T21:27:17Z")

</div>

Hi all,

I want to create a customised dashboards for monitoring kuberenetes in cloud. Right now we are using the default dashboards, but wish I can customise more to suit my needs. For an instance, the current dashboards provide a feature to monitor the CPU usage, on the whole, we thought it might be more helpful to know how much each container use each beat.

PS: I am aware of creating the custom visualizations and adding to the dashboard. But wish to know if there is a way to manage the dynamic changes. Like the default dashboards. I tried to this by adding a new horizontal bar and providing the system.cpu.usr.pct in the y-axis and in x-axis provided with an aggregation of the term with beat.host name and an additional sub-aggregation with a filter kubernetes.container.name='#####' but there is no data in the graph and the visualization is empty.

 ![25 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f95d4c4b4ceb78e9138df74633d3f751e9475f1.png)

In this screenshot there is a spelling mistake for kubernetes i corrected and tried but didnt get any output.Also i tried changing filter with double quotes (kubernetes.container.name="#####"), without any quotes (kubernetes.container.name=#####) also.

Thanks,  
Kanthi.

---

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 17, 2018, 10:30pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/2 "2018-01-17T22:30:20Z")

</div>

I just realized that I need to add 2 aggregations 1 for beat.hostname and another for [kubernetes.container.name](http://kubernetes.container.name). Is there any option to do so? I added significant terms and [beat.name](http://beat.name) in primary aggregation and the following command in json-input but i know something is wrong

{  
"script": {  
"inline": "doc['[kubernetes.container.name](http://kubernetes.container.name)'].value=####",  
"lang": "painless"  
}  
}

And tried this as well,

`{ "query": { "match": { "kubernetes.container.name": { "query": "###", "type": "phrase" } } } }`

and got this error

````auto
Error
Visualize: [illegal_argument_exception] [significant_terms] unknown field [query], parser not found```
````

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [January 18, 2018, 5:42pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/3 "2018-01-18T17:42:57Z")

</div>

I'm a little confused because it seems you have multiple questions here. The JSON input that you're entering into only supports the actual parameters expected by the Elasticsearch aggregation, and I don't think it's quite what you want.

You mentioned that you need to add 2 aggregations. Could you split series by [kubernetes.container.name](http://kubernetes.container.name) and then add another split (either x-axis or chart) by [beat.name](http://beat.name)?

---

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 18, 2018, 10:21pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/4 "2018-01-18T22:21:31Z")

</div>

I did the same, split series by filters with kubernetes.container.name="kube-proxy" and in x-axis with significant term and beat.hostname

 ![05 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/3/0306bd9f89d5e82fa432e1127db62baaa4af62f9.png)

No output ☹

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [January 18, 2018, 10:37pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/5 "2018-01-18T22:37:00Z")

</div>

Sorry, I meant do a split with a terms aggregation, not a filters aggregation. Could you try that?

---

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 18, 2018, 10:44pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/6 "2018-01-18T22:44:28Z")

</div>

Tried that too, split series term with kubernetes.container.name and again in x-axis with a significant term of beat.hostname. I don't know what is wrong ☹

 ![37 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/a/2ab1419b5f3314c4632a31714cbd2203362fe997.png)

This works fine when I try to find CPU usage with 1 aggregation i.e. beat.hostname but doesnt work when i add another aggregation

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [January 18, 2018, 10:58pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/7 "2018-01-18T22:58:19Z")

</div>

Hmm... Do the documents containing [kubernetes.container.name](http://kubernetes.container.name) also have system.cpu.user.pct?

---

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 18, 2018, 11:04pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/9 "2018-01-18T23:04:25Z")

</div>

Not sure how to check that. Sorry i am very new to this and if you mean if both are in same index then yes

---

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 18, 2018, 11:07pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/10 "2018-01-18T23:07:51Z")

</div>

Resolved. Sorry i found out the mistake. It was not using the same term

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2018, 11:07pm UTC](https://discuss.elastic.co/t/json-input-for-kibana-dashboards/115946/11 "2018-02-15T23:07:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
